CVE-2026-32110: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-32110 is a Server-Side Request Forgery (SSRF) vulnerability in SiYuan, a personal knowledge management system developed by b3log. The /api/network/forwardProxy endpoint accepts user-controlled URLs and forwards HTTP requests from the server without validating the destination, enabling authenticated users to reach internal networks, localhost, and cloud metadata services. All versions up to and including 3.5.9 are affected; the vulnerability was disclosed on March 11, 2026, and fixed in version 3.6.0. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, SiYuan Advisory).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery). The vulnerable code resides in /kernel/api/network.go (lines 153–317), where the forwardProxy function extracts a user-supplied url parameter and only validates its format via url.ParseRequestURI() — it does not block requests to private IP ranges (e.g., 169.254.169.254), loopback addresses, or internal hostnames. The full HTTP response body and headers are returned to the caller, making this a "full-read" SSRF. Exploitation requires only valid authentication credentials (low privilege), no user interaction, and is reachable over the network with low attack complexity (SiYuan Advisory, GitHub Advisory).

Impact

Successful exploitation allows any authenticated user to perform internal network reconnaissance, enumerate internal services, and access cloud instance metadata endpoints (e.g., AWS/GCP/Azure IMDS at 169.254.169.254) to steal IAM credentials or other sensitive configuration data. The server acts as a trusted proxy, bypassing perimeter firewalls and network segmentation controls. Confidentiality and integrity impacts are rated High, with a Low availability impact, reflecting the risk of credential theft, data exfiltration, and potential lateral movement into internal infrastructure (SiYuan Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, providing a complete step-by-step reproduction sequence requiring only authentication and a crafted HTTP POST request. Feedly threat intelligence classifies the PoC confidence as high, noting the advisory includes the exact request format and payload needed to exploit the vulnerability against a real SiYuan deployment. No in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.038% (0.06% per GitHub Advisory), indicating a currently low but non-negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, SiYuan Advisory).

Exploitation steps

  1. Authenticate: Log into the SiYuan instance using valid credentials (access auth code) and capture the authenticated session cookie (siyuan=<value>).
  2. Identify the target endpoint: Confirm the SiYuan instance is running a version ≤ 3.5.9 and that the /api/network/forwardProxy endpoint is accessible.
  3. Craft the SSRF request: Construct an HTTP POST request targeting the proxy endpoint with a JSON body specifying an internal or metadata URL as the destination:
POST /api/network/forwardProxy HTTP/1.1
Host: <siyuan-host>
Cookie: siyuan=<authenticated-cookie>
Content-Type: application/json
Content-Length: 102

{"url":"http://169.254.169.254/metadata/v1/","method":"GET","headers":[],"payload":"","timeout":7000}
  1. Retrieve the response: The server forwards the request to the specified URL and returns the full response body and headers, exposing cloud metadata, IAM tokens, or internal service data.
  2. Expand access: Use retrieved credentials or internal service information (e.g., AWS IAM keys from metadata) for lateral movement or further privilege escalation within the cloud environment or internal network (SiYuan Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the SiYuan server process to 169.254.169.254 (cloud metadata), 127.0.0.1/::1 (localhost), or RFC-1918 private IP ranges (10.x.x.x, 172.16–31.x.x, 192.168.x.x) that are not part of normal application traffic.
  • Logs: SiYuan access logs showing repeated POST requests to /api/network/forwardProxy with JSON bodies containing internal, loopback, or metadata service URLs; unusual response sizes from this endpoint indicating successful data retrieval.
  • Process: The SiYuan server process initiating unexpected outbound TCP connections to internal hosts or cloud metadata endpoints on port 80/443.
  • Application: Authenticated API calls to /api/network/forwardProxy from user accounts that do not normally use this feature, especially with short intervals suggesting automated scanning of internal IP ranges (SiYuan Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.6.0 or later, which addresses the vulnerability by implementing proper URL destination validation in the forwardProxy endpoint. As a network-level workaround, implement egress filtering on the host running SiYuan to block outbound connections to cloud metadata IP ranges (169.254.169.254) and internal RFC-1918 address spaces. Additionally, restrict access to the SiYuan instance to trusted users only and consider placing it behind a network boundary that limits exposure (GitHub Advisory, SiYuan Advisory).

Community reactions

The vulnerability was reported by security researchers ritikchaddha and neo-ai-engineer and disclosed via GitHub's coordinated vulnerability disclosure process. Brief community discussion was observed on Bluesky and Mastodon shortly after disclosure, and the advisory was picked up by several vulnerability tracking services including VulnDB, CVEFeed, and ENISA's EUVD. No major vendor statements or significant media coverage beyond standard vulnerability aggregation have been noted (SiYuan Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management